Movatterモバイル変換


[0]ホーム

URL:


FIRST.Org

JoinDetails about FIRST membership and joining as a full member or liaison.LearnTraining and workshop opportunities, and details about the FIRST learning platform.ParticipateRead about upcoming events, SIGs, and know what is going on.CommunityCommunity and Capacity Building.

Passive DNS Exchange

Archived Special Working Group
Also, in the near future, the Passive DNS Exchange SIG will retire - as soon as the IETF approval has been achieved. At the time of publishing, the latest version of the draft is on the IETF Web sitehere. We are happy that with this another SIG has successfully reached its goal.

Mission

This group works to define a common output format of Passive DNS Servers which clients can query. Over time, since the initial announcement of Passive DNS replication at the 17th Annual FIRST Conference on Computer Security by Florian Weimer, multiple Passive DNS Implementations were developed. This standard proposes a common output format to make Passive DNS information more universally useable.

Goals/Deliverables

The initial goal of this SIG was to collaboratively develop a common output format (COF) for Passive DNS data.As a result of this SIG, anInternet Draft was published on September 9th 2014.

The lastest version can be found on theIETF site. The source code of the standard can be foundon github. Change requests or discussions are welcome on github or on the mailing list.

Code

Apart from definining the standard, farsight and the group added aMISP module calledcof2misp which can import COF into MISP. There, the full power of the MISP correlation engine can be employed to find matching indicators of compromise.Therefore, by importing the COF format into MISP, we can pivot back and forth between passive DNS databases and MISP.

If you want to try out the cof2MISP module and if you are a member of FIRST, thehttps://misp.first.org instance has the cof2MISP module installed, and you can try correlating events.If you need to get access to passive DNS DB servers, you can ask:

Status quo

Next steps

Authors


[8]ページ先頭

©2009-2026 Movatter.jp